Application Security Engineering Manager

Seattle, Washington, United States

Full Time Senior-level / Expert USD 30K - 110K *
Qualtrics logo

Qualtrics

Qualtrics empowers companies to capture and act on customer, product, brand & employee experience insights in one place.

View all employer listings

Apply now Apply later

Company Description

At Qualtrics, our mission is to close experience gaps—the costly differences between what customers and employees expect, and what they’re receiving. 13,000+ organizations worldwide and more than 80% of the Fortune 100 rely on the Qualtrics Experience Management Platform™ to collect, analyze, and act on feedback—more feedback than they ever thought possible. With Qualtrics XM, organizations can manage the four core experiences of business—customer, employee, product, and brand experience. Organizations can be at every meaningful touchpoint, for every experience, and predict what will resonate most with customers and employees.

The Challenge

As Qualtrics continues to expand the Experience Management (XM) SaaS platform, we must ensure that we’re protecting our customers and their data by building and operating secure systems. With over one thousand software & system engineers contributing to Qualtrics XM every day, we have a large attack surface to evaluate and secure. This role is critical to this mission.

Qualtrics is seeking an experienced security engineer with a passion for security and demonstrated leadership abilities to manage our Application Security team. This is a new role reporting to the head of platform security that includes a mix of people management, hiring, strategy, program operations and hands-on security engineering responsibilities. 

The Application Security team is responsible for measures to improve and ensure the security of web & mobile applications, code and related components in Qualtrics SaaS products (including those of our acquired companies). The team owns secure development standards and training, security testing tools focused on the application layer (e.g., SAST, DAST, IAST, SCA), threat modeling, penetration testing, red team, bug bounty and vulnerability disclosure programs. Application Security works in collaboration with other teams within the Information Security organization, including infrastructure and cloud security, vulnerability management, network security, security operations and incident response, and security assurance.

A Day in the Life

  • Develop and execute the product & application security architecture and program strategy; align and communicate roadmaps with stakeholders
  • Support and manage a team of security engineers through regular 1-on-1 sessions and team meetings, coaching, workload management and performance reviews
  • Review source code & software/system designs, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices
  • Leverage your accumulated subject matter expertise of Qualtrics applications, systems and code to propose and drive architectural improvements which address classes of security flaws in the platform
  • Document and improve secure development lifecycle processes, standards and guidelines
  • Deliver training and provide mentoring to software engineers on security topics
  • Facilitate threat modeling exercises to ensure optimized security design decisions are being made
  • Document remediation recommendations and collaborate with engineers to ensure vulnerability findings are successfully and efficiently addressed
  • Oversee bug bounty and vulnerability disclosure programs, including the triage and validation of reported findings
  • Oversee internal purple and red team exercises to proactively evaluate Qualtrics environments for security flaws
  • Direct the selection, design, development, implementation and management of automated security testing tools; maintain relationships with product vendors and manage contract lifecycles

The Expectation for Success

You will define and drive improvements to the product and application security program; hire, mentor, and support a team of skilled security engineers; and work effectively with the Qualtrics engineering organization and fellow security team members to protect our customers and their data by building and operating secure systems.

Skills That Will Lead to Success

  • Bachelor’s degree in Computer Science or a related field
  • Over 12 years of relevant work experience
  • Experience as a senior/staff/lead security engineer in product or application security
  • Experience leading security projects and initiatives that require collaboration with teams across an organization
  • Sound understanding of application security vulnerabilities (e.g., OWASP Top 10), defense techniques and security best practices, including language-specific security practices and present-day threats
  • Experience with modern application development languages and frameworks (e.g., Node.js, Java, Golang, Python, React, Angular)

Preferred Qualifications

  • Experience with assessing/securing large, complex SaaS applications
  • One or more relevant security certifications (CISSP, CISM, CEPT, CMWAPT, CPT, CEH, LPT, GWAPT, GPEN, GXPN, OSCP)
  • Two or more years of experience as a people manager
  • Use of agile methodologies for project management
  • Manual web application penetration testing experience, including the use of professional penetration testing tools (e.g., Burp Suite)
  • Strong familiarity with AWS, Docker, Kubernetes, Linux and similar infrastructure/technologies
  • Experience securing iOS/Android mobile apps
  • Prior full time software development experience
* Salary range is an estimate based on our salary survey at salaries.infosec-jobs.com
Job perks/benefits: Career development
Job region: North America
Job country: United States
Job stats:  3  0  0
  • Share this job via
  • or

Other jobs like this

Explore more Cyber Security career opportunities

Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.